Privacy Policy
Nur an-Nur is a Muslim companion app. Worship is between you and Allah — we built the app so that as little of it as possible ever touches our servers. This page explains, honestly and specifically, what data we handle, why, and what we never do with it.
The short version
- A basic account is an email address and an optional name; optional profile sync can also store the preferences you choose.
- No third-party trackers, no ad networks, no data brokers. Analytics is off by default; if you opt in, only limited first-party usage events are sent to our server.
- Your worship data — reading positions, streaks, bookmarks, prayer logs — stays on your device. Export creates a backup file on your device; Nur does not upload that file.
- Nur Live is the hosted companion. Your current message and recent Live context are sent when you submit a message, passing through our service and configured AI providers.
- Personal profile sync is separate and optional. It does not include worship logs, reading history, or companion conversations.
- You can delete your account inside the app at any time.
What we collect
Account information. When you create or use an account, it consists of your email address and, optionally, a name you choose to share. We use your email to sign you in (including six-digit verification codes), to restore a Nur+ purchase across devices, and to respond when you contact us.
Pseudonymous install identifier. The app generates a random identifier for this installation, along with its platform and app version. It is sent when registering the installation, using hosted Nur for per-install quota and abuse control, and attributing a referral. It can also help link verified Nur+ access. Optional analytics adds limited usage events to that identifier only when you opt in. It is not an advertising ID, phone number, or hardware serial, but it is still an identifier and we do not describe it as anonymous.
Location, place search, and maps. If you grant location permission or choose a place, precise coordinates are stored locally and used on your device to calculate prayer times and Qibla. Nur does not send those coordinates to its own server or to the city-name search proxy. When you type a city or place name, however, that search text goes to Nur's server and then to OpenStreetMap's Nominatim service. Nur caches a successful query and its returned place labels/coordinates for 14 days without attaching it to your account; Nominatim receives the query and Nur server's connection data. If you choose to open the optional OpenStreetMap Qibla map, the app requests map tiles from OpenStreetMap infrastructure; the tile coordinates identify the displayed area and that provider receives normal connection data such as your IP address.
Optional first-party analytics events. Analytics is off by default. If you opt in in Settings, Nur sends limited event names and times with the random install identifier to our own server. These events do not include profile answers, spiritual concerns, session names, worship logs, companion messages, or paywall reasons. There are no third-party analytics SDKs, advertising trackers, or ads, and we do not sell or rent this data.
Account-creation abuse protection. On web, Android and iOS registration, Nur can load Cloudflare Turnstile to distinguish people from automated sign-up abuse. The challenge runs only while creating an account, and Cloudflare processes browser and network signals needed to return a verification token under its own privacy terms. Native apps show it in a separate, restricted in-app browser with none of Nur’s prayer, payment, permission or sharing bridges; the provider token is validated by Nur’s server and is not used as an account credential.
Optional web push reminders. If you enable browser reminders, your browser creates a Web Push subscription. We store its unique endpoint and its p256dh and auth encryption keys so a browser push provider can deliver notifications. The endpoint normally identifies your browser's push service (for example, a service operated by Apple, Google, or Mozilla), so that provider also processes delivery data. Nur removes the server record when you disable reminders or sign out/delete through the app, and automatically removes endpoints that the push provider reports as expired (HTTP 404 or 410).
Worship data stays on your device. Your Quran reading positions, dhikr streaks, bookmarks, notes, and prayer logs are stored locally. Exporting data downloads a portable backup file for you to keep and later import; the backup file is never uploaded to or stored by Nur.
Optional personal profile sync. If you turn this on while signed in, Nur can save your name, goals, madhhab, and plan preferences to your account. Prayer logs, reading history, notes, worship streaks, and companion conversations are not included.
Companion conversations. Nur Live is hosted and has no offline-mode selector. When you submit a message, your current message and recent Live context pass through our server to the configured AI gateway — OpenRouter in the default deployment — and a selected model provider. Only if you separately enable Live personalization, those requests can also include your name; goals/focus; selected current challenge (such as anxiety, grief, family, provision, or doubt); madhhab; preferred time; reading streak; today's prayer count; and last-read verse. Every default OpenRouter inference request, including retrieval query expansion, enforces per-request Zero Data Retention routing. OpenRouter states that this restricts routing to provider endpoints that do not store or train on request data, and that OpenRouter itself does not retain prompts unless prompt logging is specifically enabled; providers still process the request transiently and may use in-memory prompt caching. If the operator changes gateway, paid-service readiness remains off until that gateway's privacy handling is explicitly verified. Do not include information you would not want processed transiently by an AI provider.
Optional external feature services. The bundled Arabic Qur'an is canonical and local. If you use online Qur'an search, translations, or recitation audio, the search term or requested ayah/page and reciter — plus normal connection data such as IP address — is sent to Al Quran Cloud. If you scan or enter a food barcode, only the barcode and normal connection data are sent to OpenFoodFacts for the product lookup; camera frames and photos stay on your device and are not uploaded. The optional OpenStreetMap tile requests are described in the location paragraph above.
Optional response reports. Tapping “Report” opens a confirmation that shows exactly what will be shared. A report is sent only after you confirm it, and includes the selected Nur response, the immediately preceding message, your reason, and any optional note. Signed-in reports are linked to your account and removed when that account is deleted. A guest report is linked only to a keyed, non-reversible hash of the random install identifier. All reports expire after no more than 180 days. Reports are separate from optional analytics.
Payments. Nur+ subscriptions are processed by Stripe (or by the Apple App Store / Google Play, if you subscribed there). We never see or store your card number. We receive only what we need to activate your subscription: its status and an identifier linking it to your account.
Emails. Sign-in and verification codes are delivered through Resend, our email delivery provider. Resend processes your email address for the sole purpose of delivering these messages.
Cookies
We use only the cookies needed for sessions and authentication. There are no tracking, advertising, or third-party cookies.
How we use your information
We use the data above to operate the features you request (sign-in, optional profile sync, Nur Live, and verified Nur+ access), deliver configuration, and keep the service secure (for example, rate-limiting sign-in attempts). We process optional analytics only with your consent, which you can withdraw in Settings. Under the GDPR and Türkiye's KVKK, other processing relies on the performance of our contract with you or our legitimate interest in securely operating the service.
A note on crisis safety. If a conversation with Nur suggests you may be in crisis, the app will show information for professional help lines. Nur is a spiritual companion, not an emergency or crisis service. Messages you send to Nur follow the hosted processing described above. Nur does not automatically contact emergency services, family, or anyone else.
Data retention
We keep account data for as long as your account exists. Expired or consumed sign-in and password-reset codes are routinely purged. If you opt in to analytics, each event is deleted after 30 days. Free-use quota records contain only keyed, non-reversible hashes and counters for the current UTC quota day; older days are removed automatically, and a successful account deletion also purges the associated account/install hashes. Successful city-name queries/results are cached for 14 days. Web Push endpoints and encryption keys are removed when you unsubscribe, when the push provider reports them expired, on a linked account deletion, or after 90 days without the app renewing that subscription. Reports expire after 180 days. Worship data and the on-device copy of your Nur conversation remain in local device storage until you clear or replace them; hosted AI providers process Live requests as described above. When you delete your account, associated live server data is removed as described below. To make deletion reliable if the quota service is briefly unavailable, Nur may hold the raw email and random install identifiers in an application-key-encrypted deletion job until that service confirms erasure; the job is retried, is not used for any other purpose, and is removed after confirmation.
Encrypted disaster-recovery backups. A protected backup made before deletion may still contain account data that existed when the backup was created. These backups are access-restricted, expire automatically within 35 days, and are never selectively restored to recreate a deleted account.
Provider deletion safeguards. Every account deletion creates short-lived safeguards for Stripe, Google Play, and Apple using only keyed, non-reversible HMAC hashes of the account email and its pre-issued provider account identifiers. These pending-provider tombstones expire within 30 days and prevent a purchase, renewal, or provider notice already in flight from recreating or attaching itself to the deleted account. Where Nur already has an active purchase or subscription record for a provider, the corresponding HMAC-only tombstone may be retained for up to 2 years (730 days) so a verified recovery is not stranded and repeated provider events remain idempotent. A manual Nur+ grant can also leave a keyed, pseudonymous integrity audit for no more than 400 days; it contains the action, plan/status/expiry, and keyed hashes, but no raw account identifier, provider reference, email, name, profile, messages, worship data, or free-form support note. AI gateway and model-provider retention can follow those providers' separate terms.
Your rights
You can access, correct, or delete your data at any time:
- Delete your account in the app: Settings → Account → Delete account. If a store subscription is active, Nur first warns you and links to subscription management, but still offers immediate deletion after explicit confirmation. A successful deletion removes your account, profile, sign-in tokens, linked analytics/reports, device links, and associated quota hashes from live systems; only the limited deletion jobs, expiring encrypted backups, HMAC provider safeguards, and pseudonymous manual-grant audit described above remain for their stated purposes and retention periods.
- Or email us at selam@nurannur.com for any access, correction, deletion, or portability request. We respond to every request.
If you are in the EU/EEA, the UK, or Türkiye, you also have the right to object to or restrict processing and to lodge a complaint with your data protection authority.
International transfers
Our servers and providers — including Stripe, Apple or Google for store purchases, Resend, browser push services, OpenRouter and its selected model provider, Al Quran Cloud, OpenFoodFacts, and OpenStreetMap/Nominatim infrastructure — may process the feature-specific data described above in countries other than your own, including outside the EU/EEA and Türkiye. Where that happens, we rely on recognized safeguards such as standard contractual clauses and our providers' own compliance programs.
Children
Users must be at least 13 to create or use an account. Nur an-Nur is not directed at children under 13, and we do not knowingly collect personal data from them. The Family shelf contains adult-guided books intended for adults or guardians to read aloud with their families; it does not offer independent under-13 accounts or child-directed services. If you believe a child under 13 has created an account, contact us and we will delete it.
Changes to this policy
If we change this policy in a meaningful way, we will update the effective date at the top and, for significant changes, tell you in the app or by email. Continued use after a change means you accept the updated policy.
Contact
Nur an-Nur · nurannur.com · selam@nurannur.com. Questions, concerns, or requests — we read everything.